Skip to main content
Image coming soon

Direct handoff of SLSA framework decisions from senior security leads

$199.00
Adding to cart… The item has been added

A tailored course, built for your situation

Direct handoff of SLSA framework decisions from senior security leads

Become the named owner of critical supply chain security outcomes with documented authority

$199 one-time
24-hour access provisioning 30-day money-back guarantee Hand-built implementation playbook
12 modules. 12 chapters per module. 144 chapters total.
12 modules, each with 12 chapters (144 chapters total), text-based, plus downloadable templates and a hand-built implementation playbook delivered alongside course access.

Who this is for

Senior technical practitioner influencing security framework adoption without formal mandate

Who this is not for

Junior admins learning Jira basics, product marketers, or executives seeking board-level summaries

What you walk away with

  • Own SLSA implementation decisions with peer-recognized authority
  • Deliver audit-ready packages for third-party reviewers without rework
  • Produce version-controlled SLSA implementation playbooks used across teams
  • Receive direct escalations from security architects on SLSA gap remediation
  • Build cross-functional influence by resolving SLSA integration blockers

The 12 modules (with all 144 chapters)

Module 1. Foundations of SLSA in enterprise toolchains
Understand how SLSA integrates with CI/CD environments common in Atlassian-supported workflows. Learn to map current tooling to SLSA Levels 0, 3 with precision.
12 chapters in this module
  1. What SLSA solves in practice
  2. Key components: Attestations, Provenance, Transparency
  3. SLSA vs SBOM: distinct roles
  4. Mapping SLSA to build integrity
  5. Common anti-patterns in rollout
  6. Role of artifact signing
  7. Integration with public registries
  8. Verifiable build pipelines
  9. Chain of custody design
  10. SLSA and regulatory alignment
  11. Toolchain gaps in Level 2
  12. Common ownership models
Module 2. SLSA Level 1 attainment playbook
Build a repeatable process for achieving SLSA Level 1 using existing Jira and build tool data. Focus on source integrity and basic provenance.
12 chapters in this module
  1. Source repository controls
  2. Branch protection standards
  3. Pull request enforcement
  4. Build trigger validation
  5. Human vs automated merges
  6. Version tagging policy
  7. Artifact naming conventions
  8. Log retention for audit
  9. Initial provenance metadata
  10. SLSA Level 1 checklist
  11. Cross-team signoff workflow
  12. Documentation for reviewers
Module 3. SLSA Level 2 achievement with automated builds
Advance to SLSA Level 2 by hardening build infrastructure and generating verifiable provenance. Use Jira project data to justify process maturity.
12 chapters in this module
  1. Dedicated build environments
  2. Immutable build outputs
  3. Reproducible builds overview
  4. Build platform isolation
  5. Service account governance
  6. Signed provenance generation
  7. Provenance schema structure
  8. Linking builds to issues
  9. Automated policy checks
  10. Provenance attestation format
  11. Time window validation
  12. Peer review of build config
Module 4. SLSA Level 3 readiness with two-party builds
Design for SLSA Level 3 using independent validation and hardened infrastructure. Leverage existing Jira workflows to demonstrate control maturity.
12 chapters in this module
  1. Two-party build requirement
  2. Independent builder setup
  3. Separation of duties
  4. Build parameter controls
  5. Buildkit vs Tekton comparison
  6. Provenance signing keys
  7. Key rotation schedule
  8. Timestamp authority use
  9. Transparency log integration
  10. Monitoring for drift
  11. Incident response linkage
  12. Audit trail completeness
Module 5. Generating and validating SLSA attestations
Master the creation and review of SLSA attestations using real-world templates. Ensure compliance with evolving security review expectations.
12 chapters in this module
  1. Attestation schema breakdown
  2. Provenance vs attestation
  3. Signing key management
  4. Sigstore overview
  5. Cosign and Rekor integration
  6. Verification script templates
  7. Automated attestation checks
  8. Attestation storage model
  9. Versioning attestations
  10. Human-readable summaries
  11. Third-party validation paths
  12. Error handling in verification
Module 6. Integrating SLSA with third-party audit cycles
Align SLSA outputs with auditor expectations. Create self-documenting packages that reduce follow-up questions and speed approvals.
12 chapters in this module
  1. Auditor information needs
  2. Packaging SLSA evidence
  3. Timeline of attestations
  4. Chain of custody narrative
  5. Common auditor questions
  6. Gaps in Level 2 audits
  7. Remediation tracking system
  8. Evidence retention policy
  9. Cross-team coordination
  10. Review cycle timelines
  11. Stakeholder communication
  12. Feedback loop from auditors
Module 7. SLSA governance across distributed teams
Lead SLSA adoption without central authority. Use Jira project patterns to show consistency and maturity across teams.
12 chapters in this module
  1. Identifying SLSA champions
  2. Standardizing build configs
  3. Templatized onboarding
  4. Metrics for compliance
  5. Peer audit process
  6. Escalation path design
  7. Conflict resolution models
  8. Documentation standards
  9. Change advisory boards
  10. Toolchain exception process
  11. Training delivery plan
  12. Feedback from developers
Module 8. SLSA and vendor risk management
Extend SLSA principles to third-party software vendors. Develop review checklists and integration standards.
12 chapters in this module
  1. Vendor attestation requirements
  2. Third-party SLSA levels
  3. Integration with procurement
  4. Risk scoring model
  5. Onboarding assessment
  6. Evidence exchange protocol
  7. Third-party toolchain audit
  8. Escalation process for gaps
  9. Contractual language
  10. Compliance tracking
  11. Remediation deadlines
  12. Termination triggers
Module 9. SLSA integration with SBOM generation
Combine SLSA provenance with comprehensive SBOMs. Deliver coherent software supply chain documentation.
12 chapters in this module
  1. SLSA and SBOM overlap
  2. Timing of SBOM creation
  3. SBOM format standards
  4. Linking SBOM to provenance
  5. CycloneDX integration
  6. SPDX compatibility
  7. Vulnerability linkage
  8. Automated SBOM updates
  9. Human review process
  10. SBOM distribution controls
  11. Retention and access
  12. Customer disclosure policy
Module 10. Incident response using SLSA artifacts
Leverage SLSA data during security incidents. Speed containment and root cause analysis with verifiable build records.
12 chapters in this module
  1. Triggering SLSA review
  2. Attestation chain analysis
  3. Provenance timeline mapping
  4. Build environment snapshot
  5. Identifying compromised stages
  6. Scope of impact assessment
  7. Rollback decision framework
  8. Communication to stakeholders
  9. Regulatory reporting
  10. Post-mortem integration
  11. Process improvement tracking
  12. Lessons from real incidents
Module 11. SLSA policy drafting for internal standards
Write clear, enforceable SLSA policies. Align with existing security frameworks and leadership expectations.
12 chapters in this module
  1. Policy scope definition
  2. Applicability statements
  3. Exemption process
  4. Enforcement mechanisms
  5. Compliance measurement
  6. Audit readiness criteria
  7. Version control for policy
  8. Stakeholder review cycle
  9. Communication plan
  10. Training integration
  11. Review and update schedule
  12. Policy exception tracking
Module 12. SLSA roadmap planning and stakeholder alignment
Build a credible SLSA rollout plan. Gain buy-in from security, engineering, and product leadership.
12 chapters in this module
  1. Assessing current state
  2. Setting maturity targets
  3. Resource planning
  4. Tooling investment cases
  5. Milestone definition
  6. Success metrics
  7. Leadership communication
  8. Progress reporting
  9. Feedback integration
  10. Adjusting timelines
  11. Cross-org coordination
  12. Celebrating milestones

How this maps to your situation

  • After a new security mandate requiring SLSA
  • During third-party audit preparation
  • When onboarding a high-risk vendor
  • Before rolling out a new build system

Before vs. after

Before
SLSA discussions happen upstream, with little visibility into decisions or documentation
After
SLSA framework decisions are handed directly to you with clear ownership and expectations

What's included with your purchase

  • 12 modules with 12 chapters each (144 chapters)
  • Downloadable templates and worked examples for every module
  • Hand-built implementation playbook delivered alongside course access
  • 30-day money-back guarantee

Delivery and format

  • Course and learning environment access provisioned within 24 hours of purchase
  • Hand-built implementation playbook delivered alongside course access

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.

Time investment: Approximately 3 hours per week over 12 weeks, with on-demand access to all materials.

How this compares to the alternatives

Unlike generic security certifications or broad compliance courses, this program focuses specifically on SLSA implementation in real-world engineering environments, with templates and workflows tailored to practitioners influencing without authority.

Frequently asked

Is this course about Jira or Atlassian tools?
No. It focuses on SLSA framework implementation in environments that may use Jira, but the content is applicable to any engineering organization securing software supply chains.
How is the course structured?
12 modules, each containing 12 chapters (144 chapters total).
Will this help me lead SLSA adoption without formal authority?
Yes. The course teaches influence patterns, documentation standards, and peer validation techniques used by practitioners who lead change without mandate.
$199 one-time. Approximately 3 hours per week over 12 weeks, with on-demand access to all materials..

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

30-day money-back guarantee· 144 chapters· Hand-built playbook included· Account access within 24 hours